The committed .mcp.json currently contains several mutable npm/npx references:
@upstash/context7-mcp@latest
@playwright/mcp@latest
- bare
@modelcontextprotocol/server-sequential-thinking
This is not evidence that any package is malicious. The issue is reproducibility / review drift: the config can stay unchanged while a future install resolves to different package code.
For deterministic review, one option is to pin reviewed exact versions and move those pins deliberately.
I verified the pattern with a passive static checker that does not execute MCP servers or download packages:
https://github.com/tomelias10/mcp-drift-check
Public config observed here:
https://github.com/commercetools/ui-kit/blob/62ca335b629de087f574af71869d68cbd3bd004c/.mcp.json
The committed
.mcp.jsoncurrently contains several mutable npm/npx references:@upstash/context7-mcp@latest@playwright/mcp@latest@modelcontextprotocol/server-sequential-thinkingThis is not evidence that any package is malicious. The issue is reproducibility / review drift: the config can stay unchanged while a future install resolves to different package code.
For deterministic review, one option is to pin reviewed exact versions and move those pins deliberately.
I verified the pattern with a passive static checker that does not execute MCP servers or download packages:
https://github.com/tomelias10/mcp-drift-check
Public config observed here:
https://github.com/commercetools/ui-kit/blob/62ca335b629de087f574af71869d68cbd3bd004c/.mcp.json